I believe this is because the unbound service initializes before the wireguard service, try manually adding an access list in unbound for your wireguard subnet.Unbound DNS -> Access ListsThis solved the same/similar issue for me.